Re: [DNSOP] rfc4641bis: ZSK-roll-frequency

Niall O'Reilly <Niall.oReilly@ucd.ie> Sat, 23 January 2010 15:46 UTC

Return-Path: <Niall.oReilly@ucd.ie>
X-Original-To: dnsop@core3.amsl.com
Delivered-To: dnsop@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id CB86F3A6944 for <dnsop@core3.amsl.com>; Sat, 23 Jan 2010 07:46:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VVURN+oiqR8l for <dnsop@core3.amsl.com>; Sat, 23 Jan 2010 07:46:10 -0800 (PST)
Received: from dakota.ucd.ie (mailhost.ucd.ie [193.1.169.34]) by core3.amsl.com (Postfix) with ESMTP id 0AEAD3A692A for <dnsop@ietf.org>; Sat, 23 Jan 2010 07:46:10 -0800 (PST)
Received: from conversion-daemon.dakota.ucd.ie by dakota.ucd.ie (Sun Java System Messaging Server 6.2-2.05 (built Apr 28 2005)) id <0KWP00901I6U4V00@dakota.ucd.ie> (original mail from Niall.oReilly@ucd.ie) for dnsop@ietf.org; Sat, 23 Jan 2010 15:46:04 +0000 (GMT)
Received: from [10.0.1.177] (bark.no8.be [83.141.81.52]) by dakota.ucd.ie (Sun Java System Messaging Server 6.2-2.05 (built Apr 28 2005)) with ESMTPSA id <0KWP00608IGPF000@dakota.ucd.ie> for dnsop@ietf.org; Sat, 23 Jan 2010 15:46:01 +0000 (GMT)
Date: Sat, 23 Jan 2010 15:46:00 +0000
From: Niall O'Reilly <Niall.oReilly@ucd.ie>
In-reply-to: <1C34A57EB724F3A68C4B5F6B@Ximines.local>
To: dnsop@ietf.org
Message-id: <4B5B19B8.805@ucd.ie>
MIME-version: 1.0
Content-type: text/plain; format="flowed"; charset="UTF-8"
Content-transfer-encoding: 7bit
References: <C77DCA5E.A431%scott.rose@nist.gov> <a06240800c77e1b276941@192.168.1.106> <alpine.LFD.1.10.1001211259410.12114@newtla.xelerance.com> <d3aa5d01001211105g18a4bb17v24d77676d42c16d6@mail.gmail.com> <a06240802c77e567387d1@10.31.200.228> <p0624083bc77e5ba23b90@10.20.30.158> <d3aa5d01001211212y658402e0v9e2c1b86b39a10a3@mail.gmail.com> <20100121202745.GZ81286@shinkuro.com> <p0624083ec77e6e9eaeac@[10.20.30.158]> <alpine.LSU.2.00.1001221656290.30231@hermes-2.csi.cam.ac.uk> <p06240870c77f8d0549af@[10.20.30.158]> <1C34A57EB724F3A68C4B5F6B@Ximines.local>
User-Agent: Thunderbird 2.0.0.23 (X11/20090817)
Cc: Niall.oReilly@ucd.ie
Subject: Re: [DNSOP] rfc4641bis: ZSK-roll-frequency
X-BeenThere: dnsop@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dnsop>
List-Post: <mailto:dnsop@ietf.org>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dnsop>, <mailto:dnsop-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 23 Jan 2010 15:46:10 -0000

Alex Bligh wrote:
> 
> 
> --On 22 January 2010 09:13:22 -0800 Paul Hoffman <paul.hoffman@vpnc.org> 
> wrote:
> 
>>>> - Regular rolling can give you a false sense of security about your
>>>> rolling process
>>>
>>> How can you have any sense of security about your rolling process if you
>>> don't exercise it?
>>
>> Why do people think the opposite of "regular" is "never"?
> 
> There seems to be some confusion of "regular" and "frequent" too.

	Not to mention conflation of "regular" and "periodic".